> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction

export const Term = ({term, children}) => {
  const terms = {
    "desired-state": "What should be true for a worker: the accounts and access they should have, given who they are and their lifecycle stage.",
    connector: "An integration with one of your systems.",
    source: "An HRIS Klef pulls its workers from.",
    target: "A connector Klef writes to.",
    "worker-model": "Klef's own record of each worker.",
    worker: "Klef's own record of one person.",
    policy: "A rule that sets the desired state for a group of workers at each lifecycle stage.",
    plan: "The set of operations needed to make reality match desired state, shown before it applies.",
    operation: "A single change described in a plan.",
    reconciler: "The engine that compares desired state to your live systems and produces a plan.",
    resource: "A reusable piece a policy uses: a script, a lookup table, or a secret.",
    segment: "A saved group of workers, defined by conditions over their attributes. A policy applies to one segment, or to everyone.",
    "lifecycle-stage": "Where a worker is right now: Pre-start, Active, Leave, Suspended, or Terminated.",
    mastering: "Taking a worker field's value from a connected system instead of your HRIS."
  };
  return <Tooltip tip={terms[term]}>{children}</Tooltip>;
};

Klef sits between your HRIS and the tools your company uses. When a worker is hired, updated, or terminated, it keeps their accounts and access in sync.

You describe the <Term term="desired-state">desired state</Term> of your workers as <Term term="policy">policies</Term>. Klef compares that to the current state of your systems and generates a <Term term="plan">plan</Term> of changes to make reality match your policies. You can review the plan before it applies, or let it apply on a schedule.

For example, this policy gives every employee a Microsoft account while they work here, emails them its first sign-in, and deactivates it when they leave:

```hcl theme={null}
policy "Employee lifecycle" {
  category = "Company-wide"
  applies  = everyone

  stage active {
    target microsoft_entra.user {
      userPrincipalName = worker.business_email
      displayName       = worker.display_name
      jobTitle          = worker.job.name
      accountEnabled    = true
      licenses          = ["SPE_E3"]
    }

    notify email "welcome" {
      send    = once
      subject = "Your Microsoft account"
      body    = "Get your first sign-in here: {{ microsoft_entra.sign_in_url }}"
      to      = [worker.personal_email]
    }
  }

  stage terminated {
    target microsoft_entra.user {
      userPrincipalName = worker.business_email
      accountEnabled    = false
      licenses          = []
    }
  }
}
```

<CardGroup cols={2}>
  <Card title="Glossary" icon="graduation-cap" href="/docs/glossary">
    Terms used across Klef
  </Card>

  <Card title="Policy Anatomy" icon="file-shield" href="/docs/policy">
    Explanation of Klef's policy model
  </Card>
</CardGroup>
